Latest CVE Feed
-
5.4
MEDIUMCVE-2025-6677
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Paragraphs table allows Cross-Site Scripting (XSS).This issue affects Paragraphs table: from 2.0.0 before 2.0.5.... Read more
Affected Products : paragraphs_table- Published: Jun. 26, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-6676
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple XML sitemap allows Cross-Site Scripting (XSS).This issue affects Simple XML sitemap: from 0.0.0 before 4.2.2.... Read more
Affected Products : simple_xml_sitemap- Published: Jun. 26, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-6675
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.8.0, from 5.2.0 before 5.2.1, from 0.0.0 ... Read more
Affected Products : miniorange_2fa- Published: Jun. 26, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-6674
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor5 Youtube allows Cross-Site Scripting (XSS).This issue affects CKEditor5 Youtube: from 0.0.0 before 1.0.3.... Read more
- Published: Jun. 26, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-5682
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Klaro Cookie & Consent Management allows Cross-Site Scripting (XSS).This issue affects Klaro Cookie & Consent Management: from 0.0.0 before 3.0.7.... Read more
Affected Products : klaro_cookie_\&_consent_management- Published: Jun. 26, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.0
MEDIUMCVE-2025-52573
iOS Simulator MCP Server (ios-simulator-mcp) is a Model Context Protocol (MCP) server for interacting with iOS simulators. Versions prior to 1.3.3 are written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MC... Read more
Affected Products :- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-49003
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, a threat actor may take advantage of a feature in Java in which the character "ı" becomes "I" when converted to uppercase, and the character "ſ" become... Read more
Affected Products : dataease- Published: Jun. 26, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Information Disclosure
-
6.1
MEDIUMCVE-2025-48923
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Toc.Js allows Cross-Site Scripting (XSS).This issue affects Toc.Js: from 0.0.0 before 3.2.1.... Read more
Affected Products : toc.js- Published: Jun. 26, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-48922
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal GLightbox allows Cross-Site Scripting (XSS).This issue affects GLightbox: from 0.0.0 before 1.0.16.... Read more
Affected Products : glightbox- Published: Jun. 26, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-48921
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Open Social allows Cross Site Request Forgery.This issue affects Open Social: from 0.0.0 before 12.3.14, from 12.4.0 before 12.4.13.... Read more
Affected Products : open_social- Published: Jun. 26, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.5
HIGHCVE-2025-6693
A vulnerability, which was classified as critical, was found in RT-Thread up to 5.1.0. This affects the function sys_device_open/sys_device_read/sys_device_control/sys_device_init/sys_device_close/sys_device_write of the file components/drivers/core/devic... Read more
Affected Products : rt-thread- Published: Jun. 26, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-6562
Certain hybrid DVR models (HBF-09KD and HBF-16NK) from Hunt Electronic have an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary OS commands and execute them on the device.... Read more
Affected Products :- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
8.1
HIGHCVE-2025-5966
Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report.... Read more
Affected Products : manageengine_exchange_reporter_plus- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2025-5366
Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read mails with subject report.... Read more
Affected Products : manageengine_exchange_reporter_plus- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-6561
Certain hybrid DVR models ((HBF-09KD and HBF-16NK)) from Hunt Electronic have an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to directly access a system configuration file and obtain plaintext administrator c... Read more
Affected Products :- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Information Disclosure
-
0.0
NONECVE-2025-3773
A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior allows an authenticated non-admin local user to extract sensitive information stored in a registry backup folder.... Read more
Affected Products :- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Information Disclosure
-
7.2
HIGHCVE-2025-3771
A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin local user to overwrite system files with SIR backup files, which can potentially cause a system crash. This was achieved by adding a mali... Read more
Affected Products :- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Path Traversal
-
0.0
NONECVE-2025-3722
A path traversal vulnerability in System Information Reporter (SIR) 1.0.3 and prior allowed an authenticated high privileged user to issue malicious ePO post requests to System Information Reporter, leading to creation of files anywhere on the filesyst... Read more
Affected Products :- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Path Traversal
-
2.3
LOWCVE-2025-6703
Improper Input Validation vulnerability in Mozilla neqo leads to an unexploitable crash..This issue affects neqo: from 0.4.24 through 0.13.2.... Read more
Affected Products :- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
-
7.2
HIGHCVE-2025-6212
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Database module in versions 3.5.11 to 3.5.19 due to insufficient input sanitization and output escaping. The unfiltered field names are stored al... Read more
Affected Products : ultimate_addons_for_contact_form_7- Published: Jun. 26, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting